Last updated: May 18, 2026 | Version: 1.0
The operator of the Inner Battery application (the "App"), available at innerbattery.com, is:
Inner Battery s.r.o., IČO: 24526746, Registered office: Nové sady 988/2, Staré Brno, 602 00
Brno, Czech Republic
Contact email: hello@innerbattery.com
Inner Battery s.r.o. acts as the data controller within the meaning of the General Data Protection Regulation (GDPR).
| Data | Purpose | Legal basis |
|---|---|---|
| Email address | Login and user identification | Contract performance |
| Nickname | Display in the app to other users | Contract performance |
| Avatar (numeric code) | Visual identification in friends list | Contract performance |
| Country code | Language and currency settings | Legitimate interest |
| Language | Displaying the app in the correct language | Legitimate interest |
| Messages (text max. 160 characters after sanitization; HTML/scripts are removed) | Core app function – sending messages + security (XSS prevention) | Contract performance |
| Friends list | Social features of the app | Contract performance |
| Payment data (Paddle) | Processing gift battery purchases | Contract performance |
| Device hash (SHA-256) | Abuse protection (limiting anonymous messages) | Legitimate interest |
| Browser user agent | Device identification for abuse prevention | Legitimate interest |
| Abuse audit records (incl. content of reported message) | Abuse moderation, review of ban legitimacy | Legitimate interest (Art. 6(1)(f)) |
| Friend relationship metadata (userRelationships: relationship state friend/nonFriend, lastMessageSeenAt, lastMessageExpiresAt, hasMessageFromMe, hiddenFromStation, banCount) | Enforcement of throttle rules (3-day friend cooldown, ALREADY_SENT_NOT_OPENED gate), detection of repeated abuse (banCount), hiding after ban or disconnect, preventing bypass of limits via disconnect-reconnect cycles | Contract performance (Art. 6(1)(b)) + Legitimate interest (Art. 6(1)(f)) |
| Usage statistics (counts of sent messages, friends, thanks, bans, last activity date) | Engagement measurement, battery state calculation, abuse protection | Legitimate interest |
| Paddle customer ID + Paddle address ID | Reference to billing address stored at Paddle (for tax documents) | Contract performance + tax obligations |
| Operational event logs — authentication, payments, gift tokens, offline queue, connections, and moderation actions (incl. text of banned messages) — with user identifier | Diagnostics, resolution of technical issues, abuse moderation (review of repeated bans) | Legitimate interest (Art. 6(1)(f) GDPR) |
| Record of consent to terms (date + per-item: age 16+, Terms of Service, Privacy Policy) | Proof of valid granular consent with three explicit user affirmations | Compliance with legal obligation (Art. 7(1) GDPR) |
| Email hash of deleted accounts (SHA-256, pseudonymized) | Preventing repeated abuse of the free trial (creating new accounts on the same email to reset the trial) | Legitimate interest (Art. 6(1)(f)) — abuse prevention |
We use your data exclusively for:
Where we rely on legitimate interest as a legal basis (country code, language, device hash, user agent), our legitimate interest consists in protecting the App against abuse and ensuring platform security and quality (e.g. limiting anonymous messages per device, correct language settings). We have conducted a balancing test to ensure that your rights and freedoms are not overridden by our interests.
We do not sell your personal information and do not share your data with third parties for marketing purposes. (CCPA/CPRA mandatory disclosure for California residents.)
Marketing emails. We currently do not send you any marketing or promotional communications. We only send transactional emails (sign-in, purchase confirmations, token expiration notices, GDPR notifications). If we introduce a newsletter or marketing communication in the future, we will comply with:
| Service | Purpose | Location |
|---|---|---|
| Google Firebase (Auth, Firestore, Functions) | App infrastructure, data storage, and server-side logic | EU (europe-north1 and europe-west1 regions) |
| Paddle.com Market Limited | Payment processing (Merchant of Record) | United Kingdom |
| Google (Sign-In) | Authentication via Google account | USA |
| Apple (Sign in with Apple) | Authentication via Apple account | USA/Ireland |
App data (user profiles, messages, friends in Firestore and Cloud Functions) is stored primarily in EU regions (Google Cloud europe-north1 and europe-west1).
Sign-In providers (Google, Apple) may process authentication data in the USA. Data transfers to the USA comply with the EU-US Data Privacy Framework (DPF), or other appropriate safeguards under Article 46 GDPR, in particular Standard Contractual Clauses (SCCs) approved by the European Commission.
Paddle.com Market Limited (based in the United Kingdom) processes payments as Merchant of Record worldwide — for tax and payment purposes, Paddle is your contractual seller regardless of your country of residence. Paddle complies with GDPR, UK GDPR, and other regional privacy standards, and maintains its own privacy policy (paddle.com/legal/privacy). The UK has an adequacy decision from the EU.
For users outside the EU: by using the service, you consent to the transfer of your data to the EU for processing. For some jurisdictions (e.g., China under Art. 39 PIPL), this constitutes explicit consent to cross-border transfer.
This section constitutes our complete cookie and local storage policy under the ePrivacy Directive 2002/58/EC. All cookies and local storage used by the app are strictly necessary for the operation of the service (authentication, offline use, local cache, bot protection). We do not use analytics, marketing, or advertising tracking cookies. We therefore do not require explicit consent (strictly necessary cookies/storage is exempt from the consent requirement).
The app stores the following data locally in your browser (localStorage, IndexedDB) for faster performance and offline use:
This data never leaves your device (except for synchronization of messages from the offline queue when connection is restored) and can be deleted at any time by clearing your browser data.
Paddle Checkout SDK. When initiating a purchase of premium features, the App loads the Paddle Checkout SDK script (paddle.com), which may store its own cookies, localStorage, or session data on your device for the purposes of payment processing, fraud prevention, and session continuity. Such data is subject to Paddle.com Market Limited's own privacy governance — see paddle.com/legal/privacy. The Operator does not have access to this data.
Cloudflare (bot protection + geographic detection). Every request to the app
passes through Cloudflare (network infrastructure), which may set its own cookies for
protection against bots and attacks (e.g. __cf_bm, cf_clearance) and
for country-of-origin detection (without identifying the user). These cookies are strictly
necessary for the secure delivery of the service and are governed by Cloudflare's policy (see
cloudflare.com/privacypolicy).
Quick-reference table — all entries are strictly necessary:
| Set by | Purpose | Retention |
|---|---|---|
| App (localStorage / IndexedDB) | Language preferences, friends and voucher cache, offline queue, PWA/onboarding flags | Until browser data cleared (typically persistent) |
| Firebase Auth (IndexedDB) | Authentication token to keep you signed in | Until sign-out or session expires |
| Firestore SDK (IndexedDB, max 10 MB) | Offline cache of your data (messages, profiles) | Automatically managed, until browser data cleared |
| Paddle Checkout SDK (paddle.com) | Payment processing, fraud prevention, session | Per Paddle privacy policy |
Cloudflare (e.g. __cf_bm, cf_clearance) |
Bot protection, geographic detection (region blocking) | Session / up to 30 min per Cloudflare |
Control over data: you can delete all local data at any time by clearing your browser data (Settings → Privacy → Clear browsing data). Doing so will also sign you out of the app, and the cache will be empty on next launch.
| Data | Retention period |
|---|---|
| User account and profile | Until account deletion by user, or automatically 90 days after license expiration. On deletion request, the account enters a 7-day cancellation window (data frozen, deletion reversible with one click); after the window expires, data is irreversibly deleted (except payment records and the 3-year consent ledger). |
| Messages | Until account deletion by user, or automatically 90 days after license expiration |
| Temporary message links | Single-use /send/ link: 30 days from creation or until 1 message is delivered. Multi-use /send/ link (Diamond): 72 hours from creation or until 300 messages are delivered. Gift link: 90 days from purchase until redeemed by the recipient. Throttle limits (message count, burst window) reset upon link expiration. |
| Gift tokens | 90 days from purchase (unredeemed token expiration) |
| Payment records | As required by law (minimum 10 years). Upon account deletion, a snapshot of email and nickname is stamped into these records for accounting trail. Paddle.com Market Limited as Merchant of Record has its own retention policy for buyer transaction data per paddle.com/legal/privacy; the Operator does not have access to Paddle-side records. |
| Abuse / ban audit records | Maximum 90 days from the event, then automatically deleted |
| Operational debug logs | Maximum 90 days (aligned with cleanupDebugLogs scheduled CF) |
| Friend relationship metadata (userRelationships — visibility, lastMessageSeenAt, lastMessageExpiresAt, hasMessageFromMe, hiddenFromStation, banCount) | For the lifetime of the account. These records are not deleted on disconnect or ban (this is intentional — they enforce throttle rules and prevent bypass of limits via disconnect-reconnect cycles). On full account deletion, all relationship metadata is deleted with the account. |
| Record of consent to terms (email, consent date, deletion-request date and deletion date, terms version) | For the duration of the account + 3 years after deletion. After account deletion we retain a minimal proof of the consent given (incl. email) on the basis of GDPR Art. 17(3)(e) (establishment, exercise or defence of legal claims — e.g. a dispute "I never agreed"). The 3-year retention corresponds to the general statute of limitations under §629 of Czech Act No. 89/2012 Coll. (Civil Code) for consumer disputes — i.e. the minimum necessary period for potential defence against a consent-related claim. Stored separately, accessible to the controller only, and automatically deleted after 3 years. Full proportionality assessment (LIA) documentation is provided upon request for supervisory-authority review purposes. |
| Email hash of deleted accounts (trialHistory, SHA-256) | Retained permanently to prevent repeated abuse of the free trial (pseudonymized hash, not the full email). Legal basis: legitimate interest (Art. 6(1)(f) GDPR) — abuse prevention. Deleting the hash would let users repeatedly activate the trial by re-registering with the same email. |
Backup snapshots (Point-in-Time Recovery + scheduled backups). For disaster recovery purposes, all App data is included in two backup layers:
Snapshots serve exclusively for data recovery after incidents (accidental deletion, data corruption, schema migration failure) — not for routine access. After account deletion, your data may persist in PITR snapshots for up to 7 days and in scheduled snapshots for up to 90 days before the backup automatically expires. This technical delay is acceptable under GDPR Art. 17 as a standard limitation of recovery infrastructure.
You have the right to:
/send/{token} link (after the in-app manual
deactivation button is implemented) or waiting for auto-expiry (30 days single / 72
hours multi).
To exercise your rights, contact us at: gdpr@innerbattery.com. We accept requests in Czech or English.
How to exercise your rights:
Automated decision-making under Article 22 GDPR. We do not carry out automated decision-making or profiling that would produce legal effects concerning you or similarly significantly affect you — except for a possible future expansion of AI for moderation, see below.
AI systems used in the App. For the operation of the App we use the following AI tools:
AI systems we do NOT use:
Your rights. You have the right to request human review of any decision that could have been influenced by AI assistance — contact gdpr@innerbattery.com. If we expand the use of AI to new purposes or to a decision-making role in the future (e.g. customer support chatbots, AI-driven moderation decisions), we will inform you transparently in accordance with the AI Act and GDPR Art. 13(2)(f) and Art. 22; proactive AI moderation of message content additionally requires a prior update of the Terms of Service §5.1.
Full LIA documentation (Legitimate Interest Assessment — necessity, proportionality, balancing test per data type) is provided upon request by email to hello@innerbattery.com for supervisory-authority review purposes.
Your data is protected by:
In the event of a personal data breach:
The app allows users to report inappropriate messages (the "delete from battery" feature with the ban author option). To enable subsequent review of these reports and protect other users, we retain an audit record of each such event:
Legal basis: Legitimate interest under Art. 6(1)(f) GDPR – protecting users against abuse and harassment, and reviewing repeated unjustified bans.
Retention: Maximum 90 days from the event. After this period, audit records are automatically and irreversibly deleted.
Access: Audit records are accessible only to the application administrator (Inner Battery s.r.o.) for moderation purposes. They are not shared with third parties.
Your rights: If you wish to know whether an audit record has been created relating to you, or request its erasure under Art. 17 GDPR, contact us at gdpr@innerbattery.com. When you delete your account (Art. 17), all audit records where you appear as reporter or banned user are automatically erased.
The app is not intended for children under 16. We do not knowingly collect data from children. If we discover that we have collected data from a child, we will promptly delete it.
If you reside in a jurisdiction where the minimum age for providing consent differs, the higher age requirement under applicable law applies.
We will notify you of material changes to this policy via an in-app announcement. By continuing to use the app after changes are published, you agree to the updated policy.
Language versions and section numbering. This Privacy Policy is issued in Czech and English versions. The Czech version is the legally binding version; the English version is provided as a convenience translation. Section numbering and structural organization may differ slightly between versions due to linguistic specifics — the two versions are substantively equivalent in content. Other interface language versions of the App are produced by machine translation and are for informational purposes only; in case of discrepancy, the Czech (or English) version prevails.
The app is available globally. Inner Battery s.r.o. (based in the Czech Republic) is the data controller within the meaning of GDPR. Depending on your country of residence, additional mandatory rights may apply. To exercise any rights, contact gdpr@innerbattery.com — we accept requests in Czech or English.
| Region | Applicable law | Key rights (beyond GDPR) | Complaint authority |
|---|---|---|---|
| 🇪🇺 EU/EEA | GDPR + national transpositions | Full rights under Art. 12–22 (see §7) | National DPA or Czech ÚOOÚ (uoou.cz) |
| 🇬🇧 UK | UK GDPR + DPA 2018 | Same as EU | ICO (ico.org.uk) |
| 🇺🇸 USA — CA, VA, CO, CT, UT, TX, OR, FL and others | CCPA/CPRA + state privacy laws | Opt-out of sale (we don't sell), opt-out of sharing for advertising, "Right to know" | State AG or CPPA (California) |
| 🇯🇵 Japan | APPI (rev. 2022) | Disclosure, correction, suspension of use | PPC (ppc.go.jp) |
| 🇨🇳 China | PIPL (2021) | Cross-border consent — data transferred to EU for processing; your use = explicit consent under Art. 39 PIPL | CAC (cac.gov.cn) |
| 🇰🇷 Korea | PIPA | Access, correction, deletion, opt-out | PIPC (pipc.go.kr) |
| 🇧🇷 Brazil | LGPD | Rights similar to GDPR | ANPD (gov.br/anpd) |
| 🇨🇦 Canada | PIPEDA + Quebec Law 25 | Access, correction, withdrawal of consent | OPC (priv.gc.ca) |
| 🇦🇺 Australia | Privacy Act + APPs | Access, correction | OAIC (oaic.gov.au) |
| Other (India DPDP, Singapore PDPA, South Africa POPIA, …) | Local privacy laws | We endeavor to respect the substance — contact hello@innerbattery.com | Local regulator |
Local representatives: we currently have no designated regional representatives (CCPA agent, Japan APPI representative, PIPL local representative, etc.). We will establish local representation as the user base grows in each region.